Basavaraj Banakar🇮🇳 Profile picture
n00b | ಕನ್ನಡಿಗ❤️ | @basubanakar@infosec.exchange
Sep 23, 2022 7 tweets 2 min read
Akamai WAF Bypass read internal files via SSRF

1. target[.]com/download?url=file:///etc/passwd (Blocked by akamai waf)

#bugbountytips #bugbounty #ssrf #wafbypass #hacking 2. target[.]com disclosing internal ip in the response header ex: X-Server: 10.136.166.91